Description
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
Published: 2026-06-30
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitHub Enterprise Server suffered a UI misrepresentation flaw that lets an OAuth application obtain the manage_runners:org permission without it being visibly displayed on the consent screen. An attacker can create such an application and trick a victim into authorizing it, thereby granting the application unintended access to manage the organization’s runners. The flaw, CWE‑451, allows the attacker to add, modify, or delete runners, potentially disrupting CI/CD pipelines. The issue exists in all releases before 3.22 and was addressed in the listed patched versions.

Affected Systems

All GitHub Enterprise Server releases before version 3.22 were affected. The vulnerability was fixed in releases 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20. Administrators should upgrade to one of these patched releases.

Risk and Exploitability

The CVSS score is 4.8, and the EPSS score is below 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a human victim to approve a deceptive OAuth application, typically through social engineering. The likely attack vector is inferred to be a social engineering phishing‑like attack where a user is persuaded to approve a malicious OAuth application. Once authorized, the attacker gains the ability to manage organization runners, which can be used to alter pipeline behavior and potentially disrupt CI/CD operations.

Generated by OpenCVE AI on July 21, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GitHub Enterprise Server to a patched release such as 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, or 3.16.20.
  • Revoke any OAuth tokens that include the manage_runners:org scope and audit granted tokens for unnecessary permissions.
  • Review all applications that request excessive scopes and remove any obsolete or suspicious entries.

Generated by OpenCVE AI on July 21, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17. This vulnerability was reported via the GitHub Bug Bounty program. A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
References

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Github
Github enterprise Server
Vendors & Products Github
Github enterprise Server

Tue, 30 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Description A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program. A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17. This vulnerability was reported via the GitHub Bug Bounty program.
References

Tue, 30 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
Title UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen
Weaknesses CWE-451
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Github Enterprise Server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published:

Updated: 2026-07-01T15:37:28.521Z

Reserved: 2026-05-20T17:12:51.109Z

Link: CVE-2026-9106

cve-icon Vulnrichment

Updated: 2026-07-01T15:37:23.482Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T18:00:04Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information